2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-43222 | CRITICAL | 9.8 | 0.8% | Sep 27, 2023 | SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file. |
| CVE-2023-43216 | CRITICAL | 9.8 | 1.2% | Sep 27, 2023 | SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php. |
| CVE-2023-43187 | CRITICAL | 9.8 | 45.4% | Sep 27, 2023 | A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.1... |
| CVE-2023-43154 | CRITICAL | 9.8 | 1.0% | Sep 27, 2023 | In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during l... |
| CVE-2023-42657 | CRITICAL | 9.6 | 17.0% | Sep 27, 2023 | In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered. An attacker ... |
| CVE-2023-42462 | CRITICAL | 9.1 | 1.0% | Sep 27, 2023 | GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide... |
| CVE-2023-42461 | CRITICAL | 9.8 | 0.9% | Sep 27, 2023 | GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide... |
| CVE-2023-41878 | CRITICAL | 9.8 | 0.6% | Sep 27, 2023 | MeterSphere is a one-stop open source continuous testing platform, covering functions such as test tracking, interface t... |
| CVE-2023-41320 | CRITICAL | 9.8 | 32.1% | Sep 27, 2023 | GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide... |
| CVE-2023-40455 | CRITICAL | 10 | 1.0% | Sep 27, 2023 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed proc... |
| CVE-2023-40436 | CRITICAL | 9.1 | 1.0% | Sep 27, 2023 | The issue was addressed with improved bounds checks. This issue is fixed in macOS Sonoma 14. An attacker may be able to ... |
| CVE-2023-40400 | CRITICAL | 9.8 | 1.5% | Sep 27, 2023 | This issue was addressed with improved checks. This issue is fixed in tvOS 17, iOS 17 and iPadOS 17, watchOS 10, macOS S... |
| CVE-2023-3767 | CRITICAL | 9.8 | 1.5% | Sep 27, 2023 | An OS command injection vulnerability has been found on EasyPHP Webserver affecting version 14.1. This vulnerability co... |
| CVE-2023-39375 | CRITICAL | 9.8 | 0.6% | Sep 27, 2023 | SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges |
| CVE-2023-39347 | CRITICAL | 9 | 0.5% | Sep 27, 2023 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. An attacker with the ability ... |
| CVE-2023-38586 | CRITICAL | 10 | 1.0% | Sep 27, 2023 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed ... |
| CVE-2023-35071 | CRITICAL | 9.8 | 0.6% | Sep 27, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MRV Tech Logging A... |
| CVE-2023-43457 | CRITICAL | 9.8 | 1.0% | Sep 25, 2023 | An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in... |
| CVE-2023-43644 | CRITICAL | 9.8 | 0.7% | Sep 25, 2023 | Sing-box is an open source proxy system. Affected versions are subject to an authentication bypass when specially crafte... |
| CVE-2023-39640 | CRITICAL | 9.8 | 0.5% | Sep 25, 2023 | UpLight cookiebanner before 1.5.1 was discovered to contain a SQL injection vulnerability via the component Hook::getHoo... |
| CVE-2023-4521 | CRITICAL | 9.8 | 39.6% | Sep 25, 2023 | The Import XML and RSS Feeds WordPress plugin before 2.1.5 contains a web shell, allowing unauthenticated attackers to p... |
| CVE-2023-4490 | CRITICAL | 9.8 | 3.1% | Sep 25, 2023 | The WP Job Portal WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statem... |
| CVE-2023-43141 | CRITICAL | 9.8 | 0.7% | Sep 25, 2023 | TOTOLINK A3700R V9.1.2u.6134_B20201202 and N600R V5.3c.5137 are vulnerable to Incorrect Access Control. |
| CVE-2023-40163 | CRITICAL | 9.8 | 1.0% | Sep 25, 2023 | An out-of-bounds write vulnerability exists in the allocate_buffer_for_jpeg_decoding functionality of Accusoft ImageGear... |
| CVE-2023-39453 | CRITICAL | 9.8 | 1.2% | Sep 25, 2023 | A use-after-free vulnerability exists in the tif_parse_sub_IFD functionality of Accusoft ImageGear 20.1. A specially cra... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now